RSA Response to Media Claims Regarding NSA Relationship
blogs.rsa.com
blogs.rsa.com
Reuters: "Undisclosed until now was that RSA received $10 million in a deal that set the NSA formula as the preferred, or default, method for number generation in the BSafe software, according to two sources familiar with the contract."
And now the response.
RSA: "Recent press coverage has asserted that RSA entered into a “secret contract” with the NSA to incorporate a known flawed random number generator into its BSAFE encryption libraries. We categorically deny this allegation."
---> Only one part of the first sentence needs to be untrue for the allegation to be deniable. RSA did not incorporate a "known flawed" RNG, because it wasn't at that time. And that's not what the alleged contract was even about, but to make default.
RSA: "We have worked with the NSA, both as a vendor and an active member of the security community. We have never kept this relationship a secret and in fact have openly publicized it."
---> Focus on relationship not being secret, but contracts may be.
RSA: "RSA, as a security company, never divulges details of customer engagements, but we also categorically state that we have never entered into any contract or engaged in any project with the intention of weakening RSA’s products, or introducing potential ‘backdoors’ into our products for anyone’s use."
---> They had not positively known the RNG is flawed.
> Recent press coverage has asserted that RSA entered into a “secret contract” with the NSA to incorporate a known flawed random number generator into its BSAFE encryption libraries. We categorically deny this allegation.
They also admit to a business relationship with the NSA but refuse to discuss it.
They do admit that they agreed to incorporate that specific RNG for the money, that such a contract existed.
They do admit that the contract was secret - the explicit influence it was not disclosed to the customers of that product.
In essence they deny only that the specific RNG was known to be flawed, but don't even apologize for the fact that they had a clear conflict of interest that they didn't disclose to customers at the time, and didn't treat "please use method X, we'll pay you" as an unacceptably suspicious request in the first place.
That sounds good. But the don't even go near the heart of the matter, which, from the Reuters report is:
Undisclosed until now was that RSA received $10 million in a deal that set the NSA formula as the preferred, or default, method for number generation in the BSafe software, according to two sources familiar with the contract. Although that sum might seem paltry, it represented more than a third of the revenue that the relevant division at RSA had taken in during the entire previous year, securities filings show.
RSA does not deny that they took $10M to use Dual EC DRBG as the default in BSafe. Nor do they say why they did, if there is a reason other than that the NSA paid to make it so. They do not say why they took a sum which boosted their revenue by over 30% in return for no deliverables other than a change in default configuration - a couple minutes of work.
They could have tried to suggest all other options were weak for secret reasons but that seems like a pretty big risk.
We made the decision to use Dual EC DRBG as the default in BSAFE toolkits in 2004, in the context of an industry-wide effort to develop newer, stronger methods of encryption. At that time, the NSA had a trusted role in the community-wide effort to strengthen, not weaken, encryption.
If so, it's interesting in a "oh, it's like the Enron team in Arthur Andersen taking down the entire practice for a relatively small sum of money" kind of way...
Yes technically NSA probably didn't tell them at the time what the weakness is but getting $10M under the table to change a default and not asking questions is either incredible stupidity for why that might be, or they are are just lying, they figure out why that might be and did it anyway. (Yes they probably never put it in writing in any of the internal memos or emails).
Either way they lost credibility and shouldn't be trusted with security matters. Hope that $10M was worth it.
https://www.schneier.com/blog/archives/2013/12/nsa_spying_wh...
> We no longer know whom to trust. This is the greatest damage the NSA has done to the Internet, and will be the hardest to fix.
The first bullet starts out very strong. In fact it has the feel of taking NSA by the neck and helping them along to the underside of the bus (and bravo for that): "At that time, the NSA had a trusted role in the community-wide effort to strengthen, not weaken, encryption."
At that time. Had a trusted role.
The second bullet ("one of many choices ...") was ... eh.
The third and fourth bullet were basically RSA explaining that their actions are determined by others. First they relied upon NIST to stay with it, then at the last minute they followed NIST's belated lead and recommended against it. I would have thought they had enough smart and responsible people within RSA to determine whether Dual EC DRBG was safe and effective or not.
Still, loud applause for turning the NSA's head toward the underside of the bus.
Are you going to sue Reuters for libel?
why say "for anyone's use"?
Not necessarily a backdoor that is "open to anyone," so much as a backdoor that is intended to be used be any specific person/group/organization.
Liars. They publicized the $10 million deal?!
a) They have always had a relationship with the NSA as a vendor, and as a number of the security committee
b) They have never attempted to hide a)
c) As part of a) they have never signed a "secret contract" (for the mentioned 10 million)
That's their claim. Maybe they're lying about c), but you're barking up the wrong tree.
(edited for formatting)
"Recent press coverage has asserted that RSA entered into a 'secret contract' with the NSA to incorporate a known flawed random number generator into its BSAFE encryption libraries. We categorically deny this allegation."
The emphasis is mine. This quote allows for the possibility that they entered into a contract with the NSA to incorporate a random number generator that was not yet known to be flawed.
It doesn't matter if you have any other information on the security of the algorithm; the fact that they're offering you money should speak for itself.
It's in the best interests of national security for the NSA to promote both good and/or backdoored algorithms for all allied nations and their corporations.
The public cryptographic community started brute-forcing DES keys for fun in the '90s; with the NSA's budget, they could have been doing it from the beginning.
* DES keys are 64 bits, but 8 bits are for parity, so the meaningful key length is 56 bits.
It makes sense if you think about it: Both goals are useful to Uncle Sam and both require the same skill set. The trouble is it obviously creates quite the conflict of interest.
While a separate organisation might be best, even a division within NSA etc. explicitly tasked with protection rather than intelligence gathering would be preferable to the status quo, so long as its head could be publically known. In the end it comes down to there being no individual with that responsibility. You need someone who is visible in that role, whose mission is purely to protect, overseeing a staff whose mission is purely to protect.
What am I missing?
If you're going to call them out on being liars about that (go for it!), might want to make it less ambiguous.
For all its worth, I think RSA probably did help out the NSA with Dual EC DRBG, but:
a) Until I see some source documents from Snowden's stash, it's going to be all very annoying because until you see the terms of the contract (and no, you can't just go by some journalist's summary), you have no idea what RSA/NSA are dancing around
b) Whatever deal there was was probably set up in some fun way to make it all nicely deniable and even plausible sounding.
Crap. They're only denying a carefully-worded strawman. They leave open:
1.) Adding support for a known-flawed PRNG for free and then entering into a secret contract with the NSA to make the already-supported PRNG the default.
2.) Entering into a secret contract with someone else (FBI?) to "incorporate" a known-flawed PRNG.
3.) Entering into a secret contract with the NSA to use a PRNG that they didn't yet know to be flawed because they didn't look at it.
etc...
Edit: Pointed out first by https://news.ycombinator.com/item?id=6952801.
Edit: You're right, they did deny it 'as reported', with "Recent press coverage has asserted ...". This could involve a creative reading of "[r]ecent press coverage", or a lie.
Edit: Also, "Crap." wasn't directed at you. I'm sorry. It was directed at RSA; these stories always get me in a lather.
I think the real kicker here isn't that RSA was intentionally including maliciously modified algorithms as much as the NSA simply bribed^Woffered them $10 million to, err, "prioritize" its inclusion. This is probably more a lesson on distrusting government offers for lucrative contracts in exchange for nifty tools more than anything, IMO.
"RSA, as a security company, never divulges details of customer engagements, but we also categorically state that we have never entered into any contract or engaged in any project with the intention of weakening RSA’s products, or introducing potential ‘backdoors’ into our products for anyone’s use."
Maybe it hinges on misleading commas and the odd "for anyone’s use" part. With some gymnastics, I might be able to interpret that as meaning "we have entered into a contract and engaged in a project with the intention of weakening RSA’s products for some people's use".
a) They have always had a relationship with the NSA as a vendor,
b) That relationship is open.
C is only implied. The NSA may have paid them $10mm, but because of B, that would not count as a 'secret deal', just a deal that was not publicized.
Anyone who bothers to read this carefully and knows the backstory about the general understanding that the DRBG was weak realizes that there is no way RSA could have not known it was compromised and they have pretty much completely confirmed the reports.
In truth, I'm not sure what is worse: that they did or didn't know what they were doing.